Have something to say?

Ready to be published? LXer is read by around 350,000 individuals each month, and is an excellent place for you to publish your ideas, thoughts, reviews, complaints, etc. Do you have something to say to the Linux community?

Conectiva alert: vim

Georgi Guninski found[1] a vulnerability[2] in vim that can be
exploited to execute arbitrary commands when the user opens a text
file specially crafted by an attacker. The vulnerability resides in
the "modelines" feature, which allows one to place some VIM commands
inside of a text file.

DESCRIPTION
Vim is a highly configurable text editor. It is an improved version
of the vi editor distributed with most UNIX systems.
Georgi Guninski found[1] a vulnerability[2] in vim that can be
exploited to execute arbitrary commands when the user opens a text
file specially crafted by an attacker. The vulnerability resides in
the "modelines" feature, which allows one to place some VIM commands
inside of a text file.
This update includes a new version of vim (6.1+patches) which,
besides the fix for the aforementioned vulnerability, contains
several other bug fixes. The vim package distributed with Conectiva
Linux 9 (vim-*-6.1-27650cl) is already patched and therefore not
vulnerable to this issue.